Essential

929 posts

Essential

Essential

@only01Essential

Bug huntoor Rust | Move | C | Solidity

-analyzer Katılım Aralık 2022
157 Takip Edilen991 Takipçiler
Essential
Essential@only01Essential·
@DeltaXV_ @MezoNetwork Great job friend 🙌, found something similar, weeks back. How much did they pay as bounty for the disclosure?
English
0
0
0
23
DeltaXV
DeltaXV@DeltaXV_·
1 months ago I've discovered a critical vulnerability in @MezoNetwork's AssetsBridge precompile which could have led to a direct theft of $1,753,958.4 ($40m if no ratelimit). happy to share the security advisory (includes full report + PoC) and mezo post-mortem write-up. github.com/mezo-org/mezod… I'm also planning to post soon an X article about this finding which will include much more context on my journey and this discovery.
English
12
9
137
7.8K
Essential
Essential@only01Essential·
Wen 1k?
Essential tweet media
Deutsch
4
0
22
824
Essential
Essential@only01Essential·
Second dupped dlt High in this project. Man, I have been suffering with way too many duplicated reports
Essential tweet media
English
11
0
74
2.7K
Essential
Essential@only01Essential·
Exactly bro. We are all want that reward. Some will say please be patience. That could go on for weeks. But if it was an attacker, you make an offer immediately. Why will a protocol receive a crit and still keep you waiting for weeks? The incentives just don't align. I have reported bugs off platforms with serious money at risk, like it was right there. Six figures, but I am still patiently waiting for them, lol.
English
1
0
2
69
0x15.eth
0x15.eth@0x15_eth·
Let’s be honest. You can’t “fight blackhats” with good intentions. Blackhats are motivated by immediate money. They spend countless hours looking for ways to break protocols because the reward is instant. Whitehats are also expected to think like attackers, find critical bugs, report them responsibly, and then pray they get paid fairly. That’s the problem!! The only real difference between a whitehat and a blackhat should be responsible disclosure. Both need the same aggressive, adversarial mindset to find critical bugs. But the incentives are completely different. A blackhat finds a bug and can drain funds immediately. A whitehat finds the same bug and has to go through uncertainty, delays, disputes, underpayment, or sometimes no bounty at all. So people will naturally ask: Why should I protect a protocol that doesn’t seem to care about security?? Why should I report a critical bug when the blackhat path pays instantly?? We can pretend everyone will “always do the right thing,” but that’s not how people behave when life-changing money is involved. At the end of the day, security is an incentive game. If protocols don’t make responsible disclosure worth it, they shouldn’t be surprised when hacks keep happening.
playboi.eth@adeolRxxxx

Another hack @AftermathFi. It’s been raining. $1.4m gone I think I have to finally say. We white hats are not in a ready position to fight against blackhats on chain. We are so bounded and limited to contests and bug bounties that our scope is dependent on these. Maybe when we see beyond ourselves, we’d be a ready match for blackhats. Those mfers are active on blocks, we are there fighting for a report to be escalated in our favor. This is becoming sad. WE CANNOT WIN, OUR TRAINING MODEL IS FLAWED.

English
13
13
81
6.9K
Killua
Killua@0x158_·
After 4 dups and a looong wait thanks to OG @0xGreed_ for working with me on this 🫡 hoping for many more wins 💪
Killua tweet media
English
11
0
54
2K
Zero cool
Zero cool@cr4shls0v3rr1d3·
@only01Essential I could make an extensive list of fraudulent web3 projects that try to scam researchers, but the list of protocols that truly care about security and take researchers' work seriously is quite short.
English
1
0
1
85
Essential
Essential@only01Essential·
While there have been a huge spike in exploits, a lot of researchers are trying to help secure as many protocols as we can, but I have noticed that the communication between protocol teams and whitehats has been really terrible. Who else is experiencing this? I only report critical bugs but still, I have reports that have been pending even acknowledgment for almost two months, while some fix and stall communications for weeks, it's tiring
English
5
1
32
1.2K
Silvermist
Silvermist@0xSilvermist·
After months of trying and many duplicates... I can say I got my first confirmed bounty report 🙌 On to the next one! 🚀
Silvermist tweet media
English
40
2
308
5.5K
jussy
jussy@jussy_world·
Meet the chain where HACKERS CASH OUT: @THORChain DPRK Hackers keep using Thorchain to launder money while chain keep collecting fees • FTX exploiter: $124M • Bybit hacker: $1.2B+ • Balancer exploiter: $120M • KelpDAO hacker: $175M (in 36h) $910K in fees from KelpDAO alone, More than their whole previous month ($709k) Team claim themselves “neutral” But was it really? While hundreds of millions got laundered through them Has this industry cared more about fees than users money?
jussy tweet media
English
106
26
245
37.1K
Essential
Essential@only01Essential·
Two new confirmed High severity bugs on @xyz_remedy
Essential tweet mediaEssential tweet media
English
9
1
113
4.2K